CVE-2025-54175 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that results in arb…
Medium CVSS: 4.6

CVE-2025-54175

QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that results in arbitrary JavaScript execution in the victim's browser when opened.

The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Vendor
Opensolution
Product
Quick.cms.ext
CWE
CWE-79
Yayın Tarihi
2025-08-20 13:15:29
Güncelleme
2025-09-08 17:08:03
Source Identifier
cvd@cert.pl
KEV Date Added
-

Kategoriler

Referanslar